Legal

Privacy Policy

This policy explains what data Nexus OS collects, how we use it, and your choices. It covers our handling of Google account data accessed through Gmail.

Last updated June 18, 2026

1. Overview

Nexus OS is an AI inbox and revenue command center that helps teams triage email, detect purchase and churn signals, and draft replies. To do this, you may choose to connect your Google account so that Nexus OS can read messages from your Gmail inbox on your behalf.

We only access your data after you explicitly grant permission through Google’s OAuth consent screen, and you can revoke that access at any time.

2. Google account data we access

When you connect Gmail, Nexus OS requests the following Google API scopes:

  • gmail.readonly — read-only access to your Gmail messages and metadata so we can triage incoming email, classify intent, and draft replies. We never send, modify, or delete email on your behalf with this scope.
  • userinfo.email — your account email address, used to identify the connected mailbox and route data to the correct workspace.

3. How we use your data

We use the Gmail data described above solely to:

  • Display and triage your inbox inside Nexus OS.
  • Detect revenue and churn signals and generate suggested draft replies.
  • Route messages to the correct workspace and team.

We do not sell your data, use it for advertising, or share it with third parties for their own purposes. Google user data is not used to train generalized AI/ML models.

4. How we store and protect your data

OAuth access and refresh tokens are encrypted at rest using AES-256 before they are written to our database, and they are only decrypted server-side when needed to call the Gmail API on your behalf. Access is scoped to your workspace and protected by row-level security so that only your team can reach your data.

5. Data retention and deletion

We retain connected-mailbox data only for as long as your Gmail connection is active. You can disconnect Gmail at any time from within Nexus OS, which deletes the stored credentials and tokens for that mailbox. You may also revoke access directly from your Google Account permissions page. Deleting your Nexus OS account removes all associated stored Google data.

6. Limited Use disclosure

Nexus OS’s use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7. Contact

If you have questions about this policy or want to request deletion of your data, contact us at support@nexus-os.app.